Principal Network Engineer - Network Segmentation - Akamai Guardicore, Illumio, Cisco Secure Workload

Habitat For Humanity Of Durham

Durham (NC)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Fidelity Investments is seeking a Principal Network Engineer to lead micro-segmentation and Zero Trust implementations across enterprise infrastructure. You will design, deploy, and optimize segmentation across data centers and cloud environments, focusing on reducing risk and improving visibility.

Requirements include 7+ years in network engineering, hands-on experience with Illumio/Guardicore/Cisco Secure Workload, and expertise in TCP/IP, routing, switching, and firewalls.

Qualifications

  • 7+ years of experience in network engineering and data center networking.
  • Hands-on experience with network segmentation platforms such as Illumio, Akamai Guardicore, or Cisco Secure Workload.
  • Experience leading or supporting large-scale network segmentation, security transformation, or migration initiatives.
  • Strong knowledge of TCP/IP networking, routing, switching, firewalls, access control policies, and network security principles.
  • Experience analyzing application dependencies, network traffic flows, and east-west communication patterns to develop segmentation policies.
  • Knowledge of Zero Trust architecture, Zero Trust Network Access (ZTNA), Secure Access Service Edge (SASE).
  • Experience implementing network security solutions across on-premises and cloud environments (AWS/Azure/GCP).
  • Experience integrating network security technologies with security monitoring and configuration management platforms such as ServiceNow.

Responsibilities

  • Lead the implementation of network segmentation and Zero Trust architectures.
  • Design, deploy, and optimize micro-segmentation across data center and cloud environments.
  • Analyze application traffic patterns to develop segmentation policies and improve visibility.
  • Collaborate with security teams to integrate network controls with monitoring and CMDB tooling.

Skills

Network engineering
Data center networking
Illumio
Akamai Guardicore
Cisco Secure Workload
Zero Trust
ZTNA
SASE
AWS
Azure
GCP
TCP/IP Networking
Firewalls
Security frameworks
Python
PowerShell
APIs
Kubernetes
Linux
Windows Server

Tools

ServiceNow

Job description

Fidelity will not provide immigration sponsorship for this position.
Job Description:

The Role

Fidelity Investments is seeking a Principal Network Engineer to help lead the implementation of network segmentation and Zero Trust architectures across our enterprise infrastructure. This role focuses on designing, deploying, and optimizing micro-segmentation solutions that enhance security, improve visibility into network traffic, and reduce cybersecurity risk. Responsibilities include analyzing application traffic patterns, developing and enforcing segmentation policies, and supporting secure communication across data center and cloud environments. By modernizing network security controls, this role plays a critical part in protecting Fidelity’s technology ecosystem and business operations.

The Expertise and Skills You Bring

  • 7+ years of experience in network engineering and data center networking
  • Hands-on experience with network segmentation platforms such as Illumio, Akamai Guardicore, or Cisco Secure Workload
  • Experience leading or supporting large-scale network segmentation, security transformation, or migration initiatives
  • Strong knowledge of TCP/IP networking, routing, switching, firewalls, access control policies, and network security principles
  • Experience analyzing application dependencies, network traffic flows, and east-west communication patterns to develop segmentation policies
  • Knowledge of Zero Trust architecture, Zero Trust Network Access (ZTNA), Secure Access Service Edge (SASE), and enterprise security frameworks
  • Experience implementing network security solutions across on-premises and cloud environments, including AWS, Azure, or Google Cloud Platform
  • Ability to troubleshoot network connectivity and security policy issues in complex enterprise environments
  • Experience integrating network security technologies with security monitoring, asset inventory, or configuration management platforms such as ServiceNow
  • Scripting or automation experience using Python, PowerShell, or APIs preferred
  • Experience with Kubernetes, container networking, Linux, and Windows server environments preferred
  • Experience working within financial services or other highly regulated industries preferred

The Team

The Network Segmentation team is part of Fidelity’s Enterprise Infrastructure and Cybersecurity organization, focused on strengthening the security of the firm’s global technology environment. We partner closely with application development teams, cybersecurity professionals, cloud engineers, and infrastructure teams to design and implement secure communication frameworks across data centers, offices, and cloud platforms. Our work enables the adoption of Zero Trust security principles while helping the business innovate safely and efficiently. Fidelity is committed to protecting client information, advancing technology innovation, and investing in our greatest asset: our people.

Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:
Category:
Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Network Engineer – Network Segmentation - Akamai Guardicore, Illumio, Cisco Secure Workload
Principal Network Engineer – Network Segmentation - Akamai Guardicore, Illumio, Cisco Secure Workload

Fidelity Investments Inc. • Durham (NC)

On-site
USD 160,000 - 230,000
Principal Network Segmentation Engineer - Zero Trust
Principal Network Segmentation Engineer - Zero Trust

Habitat For Humanity Of Durham • Durham (NC)

On-site
USD 140,000 - 190,000
Principal Network Engineer: Zero Trust & Segmentation Lead
Principal Network Engineer: Zero Trust & Segmentation Lead

Fidelity Investments Inc. • Durham (NC)

On-site
USD 160,000 - 230,000
Principal Network Engineer
Principal Network Engineer

Habitat For Humanity Of Durham • Durham (NC)

On-site
USD 120,000 - 180,000
Vice President, Network Operations
Vice President, Network Operations

Fidelity Investments • Roanoke (TX)

On-site
USD 250,000 - 350,000
Principal Network Engineer
Principal Network Engineer

Soteria Reinsurance Ltd. • Durham (NC), Northern (KY)

Hybrid
USD 140,000 - 170,000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Fidelity Investments • Durham (NC)

On-site
USD 120,000 - 180,000
VP, Architecture - Security
VP, Architecture - Security

Fidelity Investments Inc. • Westlake (TX)

On-site
USD 190,000 - 270,000
Staff Engineer
Staff Engineer

Fidelity Investments Inc. • Roanoke (TX)

On-site
USD 140,000 - 200,000
Senior Full Stack Engineer
Senior Full Stack Engineer

Fidelity Investments Inc. • Durham (NC)

On-site
USD 120,000 - 180,000